Beyond OAuth: Task-Scoped Authorization for AI Agents via Natural Language Slices
Listen
Radio episode about this paper
Transcript
Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.
Nadia: I'm Nadia, and with me are Elias and Priya, guest researcher.
Elias: Today's paper: "Beyond OAuth: Task-Scoped Authorization for AI Agents via Natural Language Slices".
Nadia: This paper introduces PAuth,
Elias: First, who's behind it and why it matters.
Title and authors: Nadia: Welcome back everyone; we’re talking about a paper titled "Beyond OAuth: Task-Scoped Authorization for AI Agents via Natural Language Slices." We're diving into how this concept tries to fix the problem where broad permissions from things like OAuth let agents do way too much.
Elias: Exactly, Nadia. This paper argues that the current setup is fundamentally misaligned with what we want an agentic web to be, specifically pointing out that existing operator-scoped authorization doesn't map well to specific user goals.
Priya: From a privacy and measurement standpoint, I’m curious how this shifts the focus from broad access to something more measurable concerning the actual data being handled during those tasks.
Nadia: That’s right, Priya; it moves us toward task-scoped authorization, which means an agent only gets permission for exactly what is required for a specific natural language task. This is a big step away from granting general capabilities tied to an operator like a transfer operator.
Elias: The paper introduces NL slices as the core mechanism here; these are symbolic specifications derived directly from the user's task and the results of previous steps, defining precisely what each service expects.
Priya: So, if we're talking about NL slices, does this imply that we can actually track *what* computation was done on the data side as well? Because I want to know what kind of measurement fidelity we can expect from this approach.
Nadia: It does, Priya; because the concept of NL slices isn't just about the call itself but also about the expected computations of all its operands. This is crucial for verifying that everything flowing through the system is legitimate and hasn't been tampered with.
Elias: And to handle those operands securely, they propose using envelopes, which are special data structures that bind each operand's concrete value to its symbolic provenance. This lets servers check if the value came from a legitimate computation rather than being fabricated by the agent.
Priya: So we’re talking about cryptographically linking every piece of data back to the original, authorized calculation path? That sounds like a strong defense against manipulation during execution.
Nadia: It is, Priya; and this approach aims to make faithful execution checkable at the server level, ensuring that every incoming call matches the task's requirements precisely. This mechanism directly addresses those "overprivileged agents" we’ve been worried about.
The paper's summary: Nadia: Now that we know what PAuth is all about—"Beyond OAuth: Task-Scoped Authorization for AI Agents via Natural Language Slices"—let's look at the actual authors and what their background suggests about the research approach.
Elias: The team behind this, including Reshabh K Sharma, Linxi Jiang, Zhiqiang Lin, and Shuo Chen from Microsoft Research, shows a strong interdisciplinary mix of security research and practical engineering implementation.
Priya: I wonder how much of this work is focused on the theoretical security guarantees versus the real-world performance aspects that you see in their evaluation metrics?
Nadia: They clearly balance both; they're not just talking about theory, but they’ve prototyped PAuth within the AgentDojo framework to test it against both standard tasks and more adversarial prompt injection scenarios.
Elias: That testing setup is key because it lets them demonstrate that their permission reasoning is precise by showing zero false positives and zero false negatives across one hundred normal tasks and six hundred thirty-four prompt-injection tasks.
Priya: Zero false negatives in the attack tests are significant; it suggests the system catches misdirection attempts effectively, which speaks to a robust information-flow control mechanism.
Nadia: That level of precision is what’s impressive, Priya; it shows that when an agent tries to do something outside its task scope, PAuth correctly raises warnings about missing permissions. It's a very clean demonstration of the system working as intended.
Elias: The focus on measuring token costs during these evaluations also gives us some insight into the computational overhead of generating and verifying these NL slices and envelopes in practice.
Priya: Measuring the token costs is important because, for privacy researchers, we need to understand if this precision comes at a prohibitive cost that might limit its deployment in resource-constrained environments.
Nadia: That’s a fair point; the paper does analyze the associated token costs, which helps ground their theoretical claims in actual operational feasibility. So as we move forward into the summary, we'll see how they actually make this precise task authorization work step-by-step.
The paper's improvements: Nadia: So, focusing on the core of "Beyond OAuth: Task-Scoped Authorization for AI Agents via Natural Language Slices," what are the main technical summaries they present about how PAuth actually functions under the hood?
Elias: The central idea is achieving faithful execution checkability at servers by introducing NL slices, which are symbolic representations of expected service calls derived from the task and upstream results.
Priya: I’m interested in what this means for the actual workflow; does this mean every single step of a complex operation has to be pre-defined symbolically before we even start?
Nadia: Not exactly pre-defined; the paper shows that each involved server derives its own NL slice using an LLM to generate imperative code that represents the task as it progresses. This happens dynamically during runtime based on the specific request.
Elias: And to make sure those calls are legitimate, they use envelopes, which bind every operand's concrete value to its symbolic provenance. This is how servers verify that all operands arise from legitimate computations and not just arbitrary agent-fabricated values.
Priya: That reliance on the envelope structure sounds like a very strong defense against indirect prompt injection because the value itself carries proof of origin and derivation.
Nadia: Precisely; this mechanism ensures that if an agent tries to change an amount or recipient mid-task, the server detects that inconsistency because the operand's signature won't match its expected symbolic provenance.
Elias: It moves away from looking at permission granularity, which they argue is impractical due to complexity and exponential permissions, toward focusing entirely on faithful execution as formulated in their proposal.
Priya: That shift in focus is interesting because it suggests that instead of trying to define an exhaustive list of every possible action, we can simply enforce a contract for the specific actions needed right now.
Conclusion: Nadia: Moving on to what the authors suggest are the specific improvements they’ve introduced beyond just proposing PAuth itself, what tangible enhancements do they point out in this work?
Elias: They focus on making the system more robust by incorporating context history into the slicing process, suggesting that an agent's memory can narrow down which permissions are actually necessary.
Priya: That contextual awareness sounds like it could be very useful for complex tasks where the immediate request is vague; it helps prune the search space for possible permissions.
Nadia: They also emphasize linking that task understanding back to existing API schemas and rate limits, making the translation from natural language intent into executable code much more practical and grounded in reality.
Elias: Furthermore, they propose a feedback loop where the agent reports on its resource usage against the defined slice, which adds a layer of transparency to how much computational allowance is being used during execution.
Priya: That transparency in resource usage is something I really value; it’s not just about security but also about understanding the operational footprint of these AI agents.
Nadia: Right, because that auditability aspect is huge for anyone trying to build trust in a system that handles sensitive workflows, and it helps manage those complex cross-departmental boundaries we discussed earlier.
Elias: This granular control over resource usage and task fidelity allows for managing multi-step workflows across different services without needing a dozen separate security approvals along the way.
Reshabh K Sharma, Linxi Jiang, Zhiqiang Lin, Shuo Chen
University of Washington · The Ohio State University · Microsoft Research
cs.CR, cs.AI, cs.PL
Submitted: 2026-03-17
Updated: 2026-08-25
License: http://creativecommons.org/licenses/by/4.0/
Importance score: 91/100
The gist: This paper introduces PAuth, a novel authorization model designed to address the security vulnerabilities inherent in the emerging "agentic web." As AI agents transition from simple automation to
Key concepts
- Task-Scoped Authorization
- This approach grants an AI agent permission only for exactly what is required to complete a specific natural language task. It shifts focus from general capabilities tied to an operator to permissions tailored precisely to the current user goal, addressing overprivileged agents.
- NL Slices
- These are symbolic specifications derived directly from a user's task and previous results. They define precisely what each service expects during a task, rather than relying on broad access scopes associated with an operator.
- Envelopes
- These are special data structures that bind each operand's concrete value to its symbolic provenance. This mechanism allows servers to verify if the data came from a legitimate computation rather than being fabricated by the agent, providing cryptographic linking.
- Context History
- Incorporating context history into the slicing process helps narrow down necessary permissions. This contextual awareness allows an agent's memory to prune the search space for required permissions, which is useful for complex or vague tasks.
Terminology
Summary
This paper introduces PAuth, a novel authorization model designed to address the security vulnerabilities inherent in the emerging agentic web.
As AI agents transition from simple automation to executing complex, sensitive workflows, traditional operator-scoped
models like OAuth become inadequate because they grant broad permissions that lead to overprivileged agents.
PAuth proposes a shift toward precise task-scoped authorization, ensuring that an agent is only permitted to perform the specific operations required for the faithful execution of a user's natural language task.
The inadequacy of OAuth
Current authorization models are misaligned with this vision
of an agentic web. In existing frameworks, a scope is tied to an operator—such as a transfer operator
—rather than the specific operation implied by a user's task. For instance, if an agent needs to transfer 100 to Bob, OAuth requires the user to grant a broad TRANSFER permission
that could allow transfers of arbitrary amounts to any recipient.
This mismatch violates the principle of least privilege and creates a scenario where overprivileged agents will become the norm rather than the exception.
The PAuth mechanism
PAuth achieves its goals through two primary technical innovations: NL slices and envelopes. The core objective is to make faithful execution checkable at servers
by ensuring every incoming call is a step precisely implied by the user’s task.
-
NL slices: These are
symbolic specifications of the calls each service expects,
derived from the task and upstream results. A slice defines not just the permitted operator, but also the expected computations of its operands. -
Envelopes: This is a
special data structure to bind each operand’s concrete value to its symbolic provenance.
By using envelopes, servers can verify that all operandsarise from legitimate computations
rather than being agent-fabricated or tampered values.
Protocol and enforcement
The PAuth protocol follows a structured flow to ensure security across multiple services. When a user submits a signed natural language task, each involved server derives its own NL slice using an LLM to generate imperative code that represents the task. During runtime, the agent issues concrete tool calls accompanied by envelopes. The enforcement process involves:
-
Searching for rules applicable to the specific tool.
-
Checking that all
assert-conditionals
are satisfied. -
Verifying that every operand is permitted by a rule and matches its symbolic provenance via the envelope's signed link to the authoritative upstream value.
This ensures that if an agent attempts a spurious operation,
such as changing a recipient or an amount, the server will detect the inconsistency and trigger an explicit authorization dialog.
Evaluation and results
The researchers prototyped PAuth within the AgentDojo framework, evaluating it across both benign settings and attack scenarios. The test suite included:
-
100 normal tasks across Banking, Slack, Workspace, and Travel suites.
-
634
forced-injection
tasks designed to simulate prompt injection attacks where an agent is steered to issue unintended calls.
The results demonstrated that PAuth's reasoning is indeed precise,
yielding zero false positives and zero false negatives.
In all benign tests, the tasks were completed successfully, while in all attack tests, PAuth correctly raised warnings about missing permissions.
Improvements for AI systems
Improvement 1: Transition from Operator-Scoped to Task-Scoped Authorization
- What the improved AI system can do: It eliminates the
overprivileged agent
problem. Instead of granting an agent broad, static permissions (e.g., a generalTRANSFERpermission that allows moving any amount to any recipient), the system grants authorization only for the specific, concrete operations implied by a user's natural language task. If a user asks totransfer 100 to Bob,
the agent is strictly authorized for that specific transaction and nothing else; any attempt to deviate—such as transferring 101 or sending it to Alice—will be automatically blocked and trigger a user consent dialog.
Improvement 2: Implementation of Symbolic Provenance via Envelopes
- What the improved AI system can do: It provides robust defense against indirect prompt injection and hallucinations. By wrapping every operand in a cryptographically signed
envelope,
the system binds concrete values (e.g.,300) to their symbolic derivation (e.g.,Citi Balance / 4). This allows receiving servers to verify not just that a value is being sent, but that the value was calculated through a legitimate, task-implied computation path rather than being fabricated by a compromised agent or altered by malicious instructions embedded in a website.
Improvement 3: Dynamic Runtime Enforcement via NL Slicing
- What the improved AI system can do: It automates the enforcement of the principle of least privilege for complex, multi-step workflows. The system uses LLMs to translate natural language tasks into imperative code, from which it extracts
NL slices
—symbolic specifications of exactly what calls a server should expect. At runtime, an enforcer uses these slices to validate every tool call against the original user intent, ensuring that the agent’s execution remainsfaithful
to the task even when interacting with multiple disparate services.
Improvement 4: Cross-Service Integrity Verification in Multi-Host Environments
- What the improved AI system can do: It enables secure, distributed agentic workflows across independent web services (e.g., via MCP). In a multi-host setting, the system allows different servers to communicate through an untrusted agent by exchanging signed envelopes. This ensures that Service B can mathematically verify that a piece of data received from the agent was authentically produced and signed by Service A according to the user's original instructions, preventing the agent from acting as a vector for data tampering between services.
Abstract
AI agents increasingly execute users' natural-language (NL) tasks by calling Web services, yet today's Web authorizes these calls through OAuth, which grants permissions over operators (e.g., TRANSFER), not operations (operator plus operands, e.g., transfer 100 to Bob). This gap cannot be closed by refining scope granularity, because operands are combinatorial, quantitative, and often derived from runtime computations across servers. Operator-scoped authorization therefore inherently overprivileges agents. We propose Precise Task-Scoped Implicit Authorization (PAuth): submitting a concrete NL task implicitly authorizes exactly the operations its faithful execution requires, even when the agent is compromised (e.g., by malware or prompt injection). Each server independently derives an NL slice, a symbolic specification of the expected call inspired by program slicing, and server-produced values are wrapped in signed envelopes that bind concrete values to symbolic provenance. Together, they enforce that every operation, not just the operator, is consistent with the user's task, closing the gap that OAuth leaves open. We evaluate PAuth on AuthBench, a benchmark we build on top of AgentDojo and cross-validate on OpenClaw, spanning five service suites with 100 benign tasks and 634 adversarial calls. All 100 benign tasks are implicitly authorized and all 634 adversarial calls are blocked. Many tasks require multiple tool calls to complete. A unique value of PAuth is that it frees users from having to approve each call with concrete operand values, including intermediate results they never specified. This enhances both security and usability.
Sources
- Securing AI Agents with Information-Flow Control
- Defeating Prompt Injections by Design
- AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs